A5/1 is in the Air: Passive Detection of 2G (GSM) Ciphering Algorithms

📅 2025-05-20
📈 Citations: 0
Influential: 0
📄 PDF

career value

213K/year
🤖 AI Summary
This study empirically assesses the persistent security risks posed by legacy encryption algorithms—particularly A5/1—in operational 2G GSM networks, focusing on downgrade attacks to 2G in 4G/5G environments and residual vulnerabilities in IoT deployments. Method: Leveraging a low-cost, passive monitoring system built on HackRF One and GNU Radio, we conducted the first large-scale analysis of Cipher Mode Command messages broadcast by 2G base stations across Germany’s three major mobile network operators (>500,000 samples), combining protocol stack decoding with signaling pattern matching to quantify real-world usage of A5/1, A5/3, and A5/4. Contribution/Results: We uncover significant inter-operator divergence in cryptographic hygiene: one operator still frequently enables the cryptographically broken A5/1, while the other two have largely migrated to A5/3 and A5/4. This work provides the first empirically grounded, large-scale evidence—using commercially available hardware—on encryption algorithm deployment practices in evolving mobile networks, informing policy and standardization efforts for cryptographic governance.

Technology Category

Application Category

📝 Abstract
This paper investigates the ongoing use of the A5/1 ciphering algorithm within 2G GSM networks. Despite its known vulnerabilities and the gradual phasing out of GSM technology by some operators, GSM security remains relevant due to potential downgrade attacks from 4G/5G networks and its use in IoT applications. We present a comprehensive overview of a historical weakness associated with the A5 family of cryptographic algorithms. Building on this, our main contribution is the design of a measurement approach using low-cost, off-the-shelf hardware to passively monitor Cipher Mode Command messages transmitted by base transceiver stations (BTS). We collected over 500,000 samples at 10 different locations, focusing on the three largest mobile network operators in Germany. Our findings reveal significant variations in algorithm usage among these providers. One operator favors A5/3, while another surprisingly retains a high reliance on the compromised A5/1. The third provider shows a marked preference for A5/3 and A5/4, indicating a shift towards more secure ciphering algorithms in GSM networks.
Problem

Research questions and friction points this paper is trying to address.

Detects ongoing use of vulnerable A5/1 in 2G GSM networks
Assesses GSM security risks from 4G/5G downgrade attacks
Measures ciphering algorithm variations among major network operators
Innovation

Methods, ideas, or system contributions that make the work stand out.

Passive monitoring of GSM ciphering algorithms
Low-cost off-the-shelf hardware for detection
Analysis of A5 algorithm usage variations
🔎 Similar Papers
No similar papers found.